Security that
demonstrably works.
Independent IT security audits for mid-sized companies — with documented proof, not an opinion.
Most gaps are not
missing controls.
They are controls that were installed, have counted as done for years — and would have achieved nothing in a real incident.
We have a firewall.
But is it in test mode? That is exactly what we found — logging everything, blocking nothing.
We have backups.
But can they be restored? Copying databases while they run produces files that often cannot be loaded back.
We delete after 14 days.
But does every system? Secondary analytics often keep accumulating for years — a GDPR problem.
A law most companies
do not know applies to them.
NIS2 is the EU cybersecurity directive. In Germany it has been law since 6 December 2025 — with no transition period.
It requires demonstrable risk management across ten areas — including backup management, access control, multi-factor authentication and supply chain security. On top of that comes mandatory reporting: significant incidents notified within 24 hours, reported within 72 hours. Management is personally liable for implementation.
affected companies in Germany — up from around 4,500
or 2% of worldwide annual turnover as the maximum fine
transition period. Obligations applied from publication
Does it apply to your company?
This assessment is indicative and does not replace legal advice. Your answers are neither transmitted nor stored — the evaluation happens in your browser.
Six areas.
Each with a verifiable result.
01Infrastructure security auditFull examination
Servers, services and networks in context: what is reachable from outside, what may talk to what internally, where controls only appear to work. The result is an action plan prioritised by risk, with effort estimates.
02Backup and restore verificationOur core method
We actually restore your backup — into an isolated environment with no network access, never touching production — and compare the contents against the original.
You receive written confirmation that recovery is possible. A backup that has never been restored is an assumption.
03NIS2 readiness analysisScope & gaps
Applicability assessment, gap analysis against the ten required risk-management areas, a reporting process for the 24- and 72-hour deadlines, and documentation for the board. Specific to your company, not a template.
04Container and network segmentationWithout downtime
If every service shares one network, a single compromised web application reaches everything: other databases, backups, monitoring. We separate them — step by step, each step individually verified and reversible, without interrupting operations.
05Logging and retention reviewGDPR
IP addresses are personal data. We check whether your retention limits apply everywhere — including analytics databases and rotated logs — and implement retention that preserves statistics while removing the personal data.
06Ongoing supportCancellable monthly
Intrusion detection maintained, updates applied, logs reviewed, a short monthly report. For companies without their own security team. No annual lock-in.
Findings from
a real audit.
The subject was a company within our own group: an online shop with payment processing, grown over several years. Same scope and rigour as any client engagement.
The firewall was blocking nothing
It had been in observation mode for months. The configuration was correct — a single switch was set to "log only". Today it enforces: from the seventh attempt per minute, requests are refused.
The offsite backup held no usable database
It captured live database files instead of a consistent dump. Such copies frequently cannot be loaded back. After correcting it we proved recovery — identical to the original.
Everything was reachable from the web service
The second website's database, the backup store, monitoring and intrusion detection — all directly reachable from the public-facing application. One break-in would have sufficed. Today that service reaches two systems.
An analytics database never deleted
2.9m requests, roughly 78,000 distinct IP addresses. Resolved without losing the statistics: daily figures preserved, personal data removed. Afterwards 5,204 addresses instead of 77,925.
Why we may show this. Because the client belongs to our own group and consented to publication. Client reports remain confidential, of course — this example instead shows what we look for, and what a finding looks like with us: a measurement, a cause, and documented remediation.
One finding, made visible.
On the left, what we found. On the right, the same systems after separation — without a minute of downtime.
What this means in practice
Before, a single break-in through the website would have reached customer data, invoices and backups. The website is the most attacked point a company has — and it was the point with the most access.
How we do it
Step by step on the running system: each service first added to its new zone, verified, and only then removed from the old one. Every step individually reversible. Downtime in this case: none.
Fixed price. Known in advance.
Security consulting is normally billed by the day with an open end. We name the price up front and hold it.
Baseline Check
A first defensible status report.
- External attack surface
- Server and service configuration
- Encryption and certificates
- Backup concept reviewed
- Report prioritised by risk
- Findings call
Infrastructure Audit
For companies running their own servers or containers.
- Everything in the Baseline Check
- Real restore test
- Network and container segmentation
- Access rights and permissions
- Logging and retention
- Intrusion detection tested for effectiveness
- Re-check after 30 days
NIS2 & Hardening
For companies within the scope of NIS2.
- Everything in the Infrastructure Audit
- Applicability assessment, documented
- Gap analysis across all ten NIS2 areas
- Reporting process, 24 / 72 hours
- Supply chain
- Policies and evidence
- Board-level presentation
Ongoing supportfrom €490 / month
Intrusion detection maintained, updates applied, logs reviewed, short monthly report. With a quarterly mini-audit from €890 / month. Cancellable monthly.
Individual work€1,290 / day
Implementing fixes, incident support, a second opinion on an existing report, or support during a certification.
If we find nothing significantYou still get the report
We will tell you — and you receive the report including evidence of what was tested. An audit with no critical findings is a good outcome.
Five steps.
Intro call
30 minutes, free. We establish scope and applicability. Not a sales call.
Proposal
Fixed price, fixed scope, confidentiality agreement and written authorisation.
Audit
On the live system, in reversible steps. Critical findings reported immediately.
Report
A summary for management, a technical section with evidence for your IT team.
Re-check
Implementation on request. After 30 days we document that the gaps are closed.
We don't only advise.
We operate.
Leaf Invest is an international team based in Hamburg, Germany. The group includes its own production systems: an online shop with payment processing, a legally compliant invoice archive, and servers that are attacked daily.
That shapes how we work. We know the situation where a change stops operations at night — from our own responsibility, not from a case study. So we change things in small steps, verify each one, and always keep a way back. You speak directly with the person auditing.
What we deliberately don't doNo vendor commission
We sell no software and take no commission from vendors. Our recommendation therefore does not depend on what we earn from it. If the right answer is "change one setting", that is what we will say.
This websiteNo cookies, no tracking
No cookies, no external fonts, no analytics. That is why you see no consent banner. For a company advising on data protection, we consider that the bare minimum.
ConfidentialityProcessed in Germany
A confidentiality agreement before any access. Credentials only as long and as broadly as necessary, then verifiably deleted. Reports delivered encrypted. Processing and storage exclusively in Germany.
Frequently asked.
What does an audit cost?
Baseline Check €2,450, Infrastructure Audit €5,900, NIS2 package from €12,500, all net. The price is fixed before we begin. Individual work €1,290 net per day. That places us mid-market.
Does NIS2 apply to my company?
The German implementing act has applied since 6 December 2025 — with no transition period. It covers companies with 50+ staff or €10m turnover across 18 sectors, an estimated 30,000 in Germany. Suppliers are pulled in through the supply chain requirements.
We assess this in the free intro call. If you are not in scope, we will say so.
How is this different from a penetration test?
A penetration test looks for ways in. That is useful and we do it too. But it does not answer the second question: do the controls you already pay for work?
Does the firewall really block? Can the backup be restored? Do retention limits actually delete? That is where the most uncomfortable findings are.
Will you need to interrupt operations?
Normally not. We work on the running system in small, individually verifiable and reversible steps. Where a brief interruption is unavoidable, we agree the window in advance.
Do you work outside the EU?
Yes. For business customers the place of supply for VAT purposes is the customer's country. Within the EU, with a valid VAT identification number, we invoice under the reverse charge procedure; outside the EU without German VAT.
We consult in German, English and Turkish.
How quickly can you start?
An intro call usually within days, the start of an audit typically in two to four weeks. For an active incident we try to free capacity at short notice.
Book an intro call.
30 minutes, free. Afterwards you will know whether NIS2 applies to you and where your largest gaps probably are.